CVE-2005-1564: High severity Bugzilla vulnerability
Published May 12, 2005
·Updated
postbug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.
Affected Software
25 affected components
Bugzilla=2.17.6
Bugzilla=2.16.1
Bugzilla=2.18-rc1
Bugzilla=2.16.2
Bugzilla=2.17.4
Bugzilla=2.10
Bugzilla=2.17.1
Bugzilla=2.16
Bugzilla=2.14.2
Bugzilla=2.14.3
Bugzilla=2.14.4
Bugzilla=2.19.1
Bugzilla=2.17.5
Bugzilla=2.17.3
Bugzilla=2.16.4
Bugzilla=2.12
Bugzilla=2.16.3
Bugzilla=2.14.5
Bugzilla=2.17.7
Bugzilla=2.17
Bugzilla=2.18-rc2
Bugzilla=2.14.1
Bugzilla=2.16.5
Bugzilla=2.14
Bugzilla=2.19.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
May 12, 2005
CVE Published
04:00 AM
May 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1564?
CVE-2005-1564 is classified as a moderate vulnerability allowing unauthorized bug entries.
2
How do I fix CVE-2005-1564?
To fix CVE-2005-1564, upgrade to Bugzilla version 2.19.3 or later.
3
Which Bugzilla versions are affected by CVE-2005-1564?
Bugzilla versions 2.10 through 2.18, 2.19.1, and 2.19.2 are affected by CVE-2005-1564.
4
Who can exploit CVE-2005-1564?
CVE-2005-1564 can be exploited by remote authenticated users.
5
What type of attack does CVE-2005-1564 facilitate?
CVE-2005-1564 facilitates an attack that allows users to enter bugs into closed products.